News: 1699545909

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

It's perfectly legal for cars to harvest your texts, call logs

(2023/11/09)


In response to five class-action lawsuits, a Washington appeals court has decided that Honda and several other automakers did nothing wrong by storing text messages and call records from connected smartphones.

Honda, Toyota, Volkswagen, and General Motors were all facing charges in separate but related class-action suits that all claimed they violated Washington state privacy laws. The cases were all dismissed in court earlier this year, and the US Court of Appeals for the 9th Circuit [1]decided [PDF] this week they weren't going to reopen the cases to further litigation.

The Circuit judges hearing the case lumped all of them together because "the factual background and legal issues are virtually identical," and dismissed the appeal not because the automakers hadn't done anything wrong, but rather because the claims didn't meet the Washington Privacy Act's (WPA) statutory injury requirements.

[2]

"To succeed at the pleading stage of a WPA claim, a plaintiff must allege an injury to 'his or her business, his or her person, or his or her reputation,'" the judges ruled. "Contrary to Plaintiffs' argument, a bare violation of the WPA is insufficient to satisfy the statutory injury requirement."

[3]

[4]

In other words, it's A-OK for your car to "automatically and without authorization, instantaneously intercept, record, download, store, and [be] capable of transmitting" text messages and call logs since the privacy violation is potential, but the injury not necessarily actual.

The 9th Circuit judges' determination was based on the dismissal of a fifth class-action lawsuit in Washington that made the same arguments against Ford, which was [5]dismissed in late October on identical grounds. One of the same 9th Circuit judges, Michael Daly Hawkins, was on the appeals panel that made both decisions.

[6]

We asked Honda and lawyers for both sides of the case to comment but haven't heard back.

[7]We already give up our privacy to use phones, why not with cars too?

[8]Ford SYNC 3 infotainment vulnerable to drive-by Wi-Fi hijacking

[9]Mozilla calls cars from 25 automakers 'data privacy nightmares on wheels'

[10]Car rental firms told: Tell your customers about in-car data slurps

Per the first amended [11]complaint [PDF] filed in the Honda case, Honda infotainment systems in vehicles manufactured from 2014 onward "store each intercepted, recorded, and downloaded copy of text messages in non-temporary computer memory in such a manner that the vehicle owner cannot access it or delete it," plaintiffs argued. "Even if the text message is deleted from the smartphone, the Honda vehicle retains a copy in on-board memory, even after the smartphone is disconnected."

The same goes for call logs, the class-action complaint argued.

Plaintiffs accusing Honda of WPA violations pointed to Maryland-based Berla Corporation, which manufactures equipment "capable of extracting stored text messages from infotainment systems" as a reason for owners to consider the data harvesting a privacy concern. According to the suit, Berla software isn't generally available to the public, and is designed for law enforcement use.

"Copies of text messages and call logs stored on Honda vehicles can be, and are, retrieved by unauthorized users of Berla's equipment without any password, fingerprint, face image, or other security measures, thus bypassing any security measures Plaintiffs and class members employ to secure data on their phones," the complaint alleged.

[12]

The Honda case and those involving Toyota, VW, and GM were all dismissed with prejudice, so the only way for the cases to go is up to the Supreme Court on further appeal. It's not immediately clear if further appeals are planned. ®

Get our [13]Tech Resources



[1] https://regmedia.co.uk/2023/11/09/honda-infotainment-privacy-appeal-decision.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZU0QM9dF37egzxewDmsvvQAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU0QM9dF37egzxewDmsvvQAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU0QM9dF37egzxewDmsvvQAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://law.justia.com/cases/federal/appellate-courts/ca9/22-35447/22-35447-2023-10-27.html

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU0QM9dF37egzxewDmsvvQAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2018/02/14/connected_vehicles_data_and_privacy/

[8] https://www.theregister.com/2023/08/14/ford_sync_vulnerability/

[9] https://www.theregister.com/2023/09/06/mozilla_vehicle_data_privacy/

[10] https://www.theregister.com/2017/12/06/car_rental_firms_in_car_data_slurps/

[11] https://regmedia.co.uk/2023/11/09/honda-infotainment-class-action-suit.pdf

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU0QM9dF37egzxewDmsvvQAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



I can see two cases here

Mishak

1) You own the car, and it retaining your information is no different than it being stored on your phone, PC, etc.

2) You do not own the car (hire, friend's, ...), where it retains the information without your consent (and probably without your knowledge).

Re: I can see two cases here

Anonymous Coward

>1) You own the car, and it retaining your information is no different than it being stored on your phone, PC, etc.

Except the maker / dealer / service tech / government can read the messages and you didn't know

>2) You do not own the car (hire, friend's, ...), where it retains the information without your consent (and probably without your knowledge).

And you are a police officer, doctor, lawyer, officer of a public company discussing non-public information

Are you professionally negligent for discussing confidential data in a hire car and then finding out that Volvo's Chinese parent company have a printout of your calls ?

Re: I can see two cases here

FrogsAndChips

>> 1) You own the car, and it retaining your information is no different than it being stored on your phone, PC, etc.

> Except the maker / dealer / service tech / government can read the messages and you didn't know

How does that differ from it being stored on your phone/PC..?

Re: I can see two cases here

Yet Another Anonymous coward

I don't take my PC into Bestbuy every 4000mi to have the fonts changed and have the blue-shirts download a copy of my 'personal art collection'

Re: I can see two cases here

Alan_Peery

The phone or the PC is the primary device on which the message is created. The car is only acting as a relay, and would not normally be expected to retain a copy of the message.

It's also an additional possible point of IT vulnerability.

It may be legal in the USA, but

Spanners

It sure as F. is illegal here!

(Presuming for the sake of argument that it's even *possible* to design
better code in Perl than in C. :-)
-- Larry Wall on core code vs. module code design